News

Google Had an Undercover Analyst Inside TeamPCP as Hackers Breached a Thousand Companies

A Mandiant persona sat in TeamPCP's roughly 12-person CanisterWorm chat from about March 2026, WIRED reported. Australian police later arrested two alleged principal participants. The AFP said the haul included more than 500,000 users' credentials.

Google Had an Undercover Analyst Inside TeamPCP as Hackers Breached a Thousand Companies

WIRED (Andy Greenberg, 18 September 2026) reported that a Mandiant undercover persona sat inside TeamPCP's private CanisterWorm chat during the group's supply-chain campaign. Google Threat Intelligence Group researcher Austin Larsen disclosed the operation in an interview ahead of a SentinelOne LABScon talk.

This is a WIRED interview disclosing an undercover monitoring posture. It is not a Google confession of illegal hacking, not a completed conviction, and not a claim that Google alone produced the arrests.

From about March, after months of building trust with an invited actor, the Mandiant persona joined a roughly 12-person inner chat. Larsen said the analyst was a fly on the wall, with guardrails and no illegal hacking.

TeamPCP's cascading campaign hit open-source and vendor targets including Trivy, LiteLLM, Checkmarx, TanStack, and Mistral AI infrastructure. Public reporting also named GitHub, Mercor, OpenAI employee devices, the European Commission, and many unnamed organizations. A Dune-themed worm called Mini Shai-Hulud automated the scale-up.

Google accessed a server of stolen credentials, notified AWS and Microsoft first so those providers could revoke access at scale, then emailed hundreds of victims. Visibility into the chat also let Google intercept an AI-assisted zero-day against a widely used login product that bypassed two-factor authentication. Google tested the exploit, warned the vendor, and got a patch. A May Google case study described that incident without naming TeamPCP.

Late last month the Australian Federal Police, with FBI assistance, arrested Ruben Ian Thomson and Louis Michael Gaebler, Australians in their early twenties, as alleged principal participants. The AFP said the haul included more than half a million users' credentials.

Larsen estimates TeamPCP took only tens of thousands of dollars in extortion, not millions. Both men are charged. Neither has been convicted.

ShinyHunters partnered with TeamPCP, then went rogue, shared a full chat log with Larsen unsolicited, and taunted the group in public. TeamPCP purged its circle and ejected Google's mole.

Larsen later followed an identity trail from a BreachForums leak that tied a CanisterWorm handle to a personal Gmail, a PayPal refund, and an illicit server backed up to the same Google Drive, then tipped the FBI. Other researchers, including Brian Krebs, also published identity clues. The AFP and FBI ran the arrests.

Related supply-chain tape includes Plugin4Shell in AI coding agents, the Trinitite npm TanStack Query codegen worm, and the Virtualizor BGP hijack malicious update.

If you run Trivy, LiteLLM, Checkmarx, TanStack, or Mistral-adjacent tooling, rotate developer tokens and cloud keys now and treat any 2026 spring-to-summer npm or vendor compromise as in-scope until your own logs say otherwise.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free